Skip to content

Order SBOM packages to have "CPython" be first as the primary package #118967

@rjb4standards

Description

@rjb4standards

Bug report

Bug description:

The SPDX SBOM shown does not meet NTIA minimum requirements, there is no creation info.
NTIA Minimum Info Requirements:
https://www.ntia.gov/sites/default/files/publications/sbom_minimum_elements_report_0.pdf

Also, this sbom does not validate using the SPDX online validator:
https://tools.spdx.org/app/validate/

Please update the SBOM to meet the NTIA minimum elements and confirm that it is valid using the oinline validator tool so that it can be processed by existing tools.

CPython versions tested on:

CPython main branch

Operating systems tested on:

Windows

Metadata

Metadata

Assignees

Labels

triagedThe issue has been accepted as valid by a triager.type-bugAn unexpected behavior, bug, or error

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions